Anubis Ransomware Halts Fairlife Milk Production in the US | #ransomware | #cybercrime


Fraud Management & Cybercrime
,
Ransomware

Gang Claims 1TB of Stolen Data and Sets Deadline for Ransom Talks

Stocks of Fairlife milk are running low at the City Acres Market in Long Island City, New York, in a photo dated July 22, 2026. (Image: Jonathan Aung)

The Anubis ransomware gang is claiming responsibility for a halt in milk production by U.S. dairy brand Fairlife after an attack disclosed July 16 by parent company Coca-Cola.

See Also: The Unstructured Data Blindspot: Why Your Most Valuable Assets Are Your Least Protected

The Russian-speaking ransomware-as-a-service operation claims to have stolen 1 terabyte of confidential data from the company and is threatening to leak it late Sunday night unless it receives a payoff. Coca-Cola told investors the attack reached production-related systems. Operations in Canada are not affected.

“The full scope, nature and impacts of the incident are not yet known,” the dairy provider said. “Product quality and safety have not been impacted. However, as a result of the incident, production operations at Fairlife in the United States are temporarily suspended.”

Anubis is demanding a “token agreement” to restore Fairlife’s systems and not leak the data, giving the company until the end of the week to “give the people back their milk.”

Fairlife generates more than $3 billion in annual retail sales from a portfolio of products including ultra-filtered milk and protein shakes.

Coca-Cola said it is working with outside advisors and cybersecurity experts to complete the incident assessment and restore the systems. The company declined to comment.

Anubis took responsibility for the hack on its data leak site Monday, where it displays Fairlife’s logo in black and white and a countdown timer below it for when the stolen data will be available for download.

The financially motivated ransomware-as-a-service group surfaced in late 2024, and its code resembled an earlier malware called Sphinx, said threat intelligence firm SOCRadar. It operates a flexible model in which affiliates conduct the attack cycle and Anubis operators supply the malware, leak sites and backend negotiation.

“What sets Anubis apart from most contemporary ransomware families is its dual execution model,” SOCRadar said in an analysis earlier this year. “In addition to standard file encryption, Anubis includes an optional destructive wipe mode that irreversibly overwrites file contents. When this mode is used, recovery remains impossible even if a ransom is paid.”

Alleged victims currently on Anubis’ darkweb site range from a North American bathroom-remodeling company and a Wyoming-based orthopedic clinic to a Milwaukee social services organization and a Colombian supermarket chain.

“Anubis affiliates most commonly gain initial access through spear-phishing emails containing malicious documents or compressed executables,” SOCRadar said. “In parallel, affiliates actively abuse exposed internet-facing services, particularly Remote Desktop Protocol (RDP). Compromised credentials, brute-force attempts or previously obtained access are used to directly deploy the ransomware.”



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW